YouTube Pledges to Block all Anti-Vaccine Content

YouTube Pledges to Block all Anti-Vaccine Content

YouTube has announced it will block all anti-vaccine content on its platform, expanding beyond COVID-19.

The video-sharing site outlined its updated medical misinformation policy in a blog post published earlier today. This includes content that alleges approved vaccines cause chronic health effects, such as autism, cancer or infertility, that they do not reduce transmission or contraction of disease or that substances in vaccines can track those who receive them.

These rules will apply both to routine immunizations for conditions like measles or hepatitis B, as well as general statements about vaccines.

YouTube explained it had “learned important lessons about how to design and enforce nuanced medical misinformation policies at scale” while tackling misinformation about the COVID-19 pandemic in conjunction with health authorities. In this process, it “looked to balance our commitment to an open platform with the need to remove egregious harmful content” and revealed it had removed more than 130,000 videos for violating its COVID-19 vaccine policies since last year.

The social media company added: “We’ve steadily seen false claims about the coronavirus vaccines spill over into misinformation about vaccines in general, and we’re now at a point where it’s more important than ever to expand the work we started with COVID-19 to other vaccines.”  

However, it said there are “important exceptions” to these new guidelines due to “the importance of public discussion and debate to the scientific process.” As such, the site will continue to allow content around vaccine policies, new vaccine trials and historical vaccine successes and failures. Additionally, personal testimonials relating to vaccines are permitted as long as the channel “doesn’t show a pattern of promoting vaccine hesitancy.”

YouTube stated: “Today’s policy update is an important step to address vaccine and health misinformation on our platform, and we’ll continue to invest across the board in the policies and products that bring high-quality information to our viewers and the entire YouTube community.”

The announcement follows the decision by YouTube on Tuesday to remove Russian state-backed broadcaster RT’s German-language channels from its site for violating its COVID-19 misinformation policy.

Many in the cybersecurity industry argue that disinformation is a cybersecurity issue. Otavio Freire, CTO at Safeguard Cyber, argued last year that: “Disinformation is a cybersecurity issue. It has already been used as a means for brand value destruction to create divisiveness and conflict within a company’s employees, used as a social engineering lure, and as a form of ransomware; where if you want the disinformation to stop, you need to pay.”

These actions come amid growing criticism of social media firms like YouTube, Facebook and Twitter for failing to stem the flood of vaccine misinformation on their sites this year. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Mental Healthcare Providers Report Data Breaches

Mental Healthcare Providers Report Data Breaches

Data breaches at two American mental healthcare providers may have exposed thousands of individuals’ personal health information (PHI). 

Horizon House, Inc., which is in Philadelphia, Pennsylvania, warned that 27,823 people might have been impacted by a cyber-attack that took place in the late winter.

The mental health and residential treatment services provider detected suspicious activity on its IT network on March 5. An investigation revealed that the healthcare provider’s IT system had been infected with ransomware. 

In a security notice, Horizon House said: “Horizon House systems were accessible by an unknown actor between March 2, 2021, and March 5, 2021, and certain data was exfiltrated from the Horizon House systems.”

A review of the files compromised in the incident determined that the unknown cyber-attacker gained access to data including names, addresses, Social Security numbers, driver’s license numbers, state identification card numbers, dates of birth, financial account information, medical claim information, medical record numbers, patient account numbers, medical diagnoses, medical treatment information, and health insurance information.

Horizon House has notified all the individuals affected by the security breach and advised them to be on the lookout for fraudulent activity. 

Meanwhile, the Samaritan Center of Puget Sound issued a data breach warning after a computer, server and other electronic equipment were stolen from its locked offices in Seattle, Washington.

Although the stolen computer and server were password-protected, the Center raised concerns that a brute-force attack could render them accessible. 

Data stored on the stolen server included the names, appointment dates, diagnoses, copies of charting content, addresses, phone numbers, copies of deposited checks, training videos, insurance information, Social Security numbers, and copies of billing statements of clients who accessed services before July 19.

The Center, which provides spiritually integrated counseling and mental health support, reported the July 19 theft to the HHS’ Office for Civil Rights as a data breach impacting 20,866 individuals. 

“The Ravenna facility has been the subject of a number of attacks and break-ins during the last year,” wrote the Center’s clinical director, Matthew Percy.

He added that physical and electronic security were both being tightened.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

More Than Two-Thirds of Organizations Are Targets of at Least One Ransomware Attack

More Than Two-Thirds of Organizations Are Targets of at Least One Ransomware Attack

Most organizations are more concerned about ransomware than other cyber-threats. This is a key finding from the 2021 Global State of Ransomware Report  by cybersecurity company Fortinet

Unveiled today, the survey also reveals that while the majority of organizations surveyed indicated they are well prepared for a ransomware attack, including employee cyber training, risk assessment plans and cybersecurity insurance, there was a clear gap in what many respondents viewed as essential technology solutions. 

Based on the technologies viewed as essential, organizations were most concerned about remote workers and devices, with Secure Web Gateway, VPN and Network Access Control amongst the top choices. While ZTNA is an emerging technology, it should be considered a replacement for traditional VPN technology. However, the low importance of segmentation (31%) was most concerning, a critical technology solution that prevents intruders from moving laterally across the network to access critical data and IP. Likewise, UEBA and sandboxing play a crucial role in identifying intrusions and new malware strains, yet both were lower on the list. Another surprise was secure email gateway at 33%, given phishing was reported as a common entry method of attackers.

Organizations More Concerned about Losing Data

The top concern of organizations regarding a ransomware attack was the risk of losing data, with the loss of productivity and the interruption of operations following closely behind. In addition, 84% of organizations reported having an incident response plan, and cybersecurity insurance was a part of 57% of those plans. Regarding paying the ransom if attacked, the procedure for 49% was to pay the ransom outright, and for another 25%, it depends on how expensive the ransom is. Of the one-quarter who paid the ransom, most, but not all, got their data back.

Ransomware Concerns Consistent Globally

While, for the most part, the findings of the survey were consistent among respondents globally, there were a few differences regionally. For example, respondents in EMEA and LATAM were more concerned about ransomware attacks and more likely to be victims than their peers in North America and APJ, (79% and 78% respectively compared to 59% in North America and 58% in APJ.) In addition, phishing lures were the primary attack vector in North America, while in APJ and LATAM, remote desktop protocol exploits and open vulnerability ports were the primary attack vectors.

The Need for Integration and Intelligence

Almost all respondents view actionable threat intelligence with integrated security solutions or a platform as critical to preventing ransomware attacks and see value in AI-driven behavioral detection capabilities.

While almost all of those surveyed felt they are moderately prepared and plan to invest in employee cyber awareness training, the survey showed that organizations need to recognize the value of investing in technologies. 

Commenting on the news, John Maddison, EVP of products and CMO at Fortinet, said: “According to a recent FortiGuard Labs Global Threat Landscape report, ransomware grew 1070% year-over-year. Unsurprisingly, organizations cited the evolving threat landscape as one of the top challenges in preventing ransomware attacks.

“As evidenced by our ransomware survey, there is a huge opportunity for the adoption of technology solutions like segmentation, SD-WAN, ZTNA, as well as EDR, to help protect against the methods of access most commonly reported by respondents,” he added. 

“The high amount of attacks demonstrates the urgency for organizations to ensure their security addresses the latest ransomware attack techniques across networks, endpoints, and clouds. The good news is that organizations are recognizing the value of a platform approach to ransomware defense.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

ICO Reveals 60% Rise in Nuisance Contact Reports

ICO Reveals 60% Rise in Nuisance Contact Reports

The UK’s Information Commissioner’s Office (ICO) recorded a 60% rise in reports of nuisance calls, texts and emails in the first six months of 2021 compared to 2020, according to official figures analyzed by litigation firm Griffin Law.

In the first half of 2021, the ICO received an average of 13,925 reports of nuisance calls, texts and emails per month; this compared to just 8680 per month throughout the whole of 2020. The disparity was even greater when comparing the total number of reports in the first half of 2020 with 2021 (38,269 vs. 83,558, an increase of 116%).

The majority of nuisance contact reports in 2021 related to telecoms services, such as broadband, tv or phone, averaging just over 2000 per month. This was followed by communication relating to banking (1059 per month) and accident claims (620 per month).

In contrast, the most frequent type of nuisance contact in 2020 was accident claims, with an average of 1946 reports per month. Interestingly, calls, texts and emails relating to telecoms services averaged just 1182 reports per month during 2020, while for banking it was 534 per month.

The month with the highest number of nuisance contact reports was March 2021, at 17,728. This compared to just 6484 reports in March 2020.

Griffin Law also noted that the most active month for nuisance calls in 2020 — October at 13,131 — is still less than five of the first six months of 2021.

Security experts believe these figures are linked to the surge in social engineering scams and cyber-attacks since the start of the COVID-19 pandemic. Ed Blake, area vice president EMEA for Absolute Software, explained: “’Nuisance’ contact has become synonymous with malicious cyber-attack attempts, which usually starts with a phishing, spam or malware email or text, sent to a recipient under the guise of a legitimate service or brand name.

“This is not to say that all reports of nuisance contact have malicious undertones, but it is certainly something that end-users and business decision-makers must be aware of, particularly as the remote working climate has increased the cyber threat facing businesses.”

In June, the ICO fined a home improvement company £130,000 for inundating consumers with nearly a million nuisance calls.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

CISA and NSA Deliver New Security Guidance for VPNs

CISA and NSA Deliver New Security Guidance for VPNs

The US authorities have released new guidance for organizations on hardening their VPNs against compromise by reducing the attack surface.

The Cybersecurity Information Sheet comes from the NSA and Cybersecurity and Infrastructure Security Agency (CISA).

It warned that multiple nation-state actors had exploited known vulnerabilities in products over the past year to steal credentials, execute arbitrary code remotely on devices, weaken and hijack encrypted communications, and read sensitive data.

“These effects usually lead to further malicious access through the VPN, resulting in large-scale compromise of the corporate network or identity infrastructure and sometimes of separate services as well,” the agencies claimed.

Their advice is to select standards-based (IKE/IPSec) VPNs from reputable vendors with a proven track record for fixing vulnerabilities quickly and mandating the use of strong authentication credentials.

Once the device has been selected, organizations can proactively harden the equipment by requiring “only strong, approved cryptographic protocols, algorithms, and authentication credentials.”

The VPN attack surface can be further reduced by patching promptly, restricting external access by port and protocol, and running only the strictly necessary features, the notice continued.

Finally, organizations were urged to protect and monitor access to and from their VPNs with intrusion prevention (IPS), web application firewalls (WAFs), network segmentation, and remote and local logging for continuous monitoring.

The warnings come after a pandemic in which VPNs used by home workers were heavily targeted by both state-backed and financially motivated cyber-criminals.

In October 2020, researchers warned that various groups were using the Zerologon vulnerability with VPN bugs to compromise victim networks.

In August last year, a major British high street retailer was called out for using VPN servers with unpatched critical vulnerabilities, which put it at risk of ransomware and other threats.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Most Third-Party Cloud Containers Have Vulnerabilities

Most Third-Party Cloud Containers Have Vulnerabilities

The vast majority of third-party code used in cloud infrastructure contains vulnerabilities and misconfigurations, which could leave organizations exposed to attack, according to Palo Alto Networks.

The security vendor’s Unit 42 Cloud Threat Report 2H 2021 used data from various public sources better to understand the threat from cloud software supply chains.

It revealed that 63% of third-party code templates used to build cloud infrastructure contain insecure configurations, while 96% of third-party container applications deployed in cloud infrastructure contain known vulnerabilities.

Unvetted third-party code can introduce vulnerabilities and malware inserted on purpose by threat actors. A Sonatype study from earlier this month revealed a 650% spike in upstream supply chain attacks of this nature.

To highlight the challenge, Unit 42 analyzed public Terraform modules and found over 2500 were misconfigured in areas such as encryption, logging, networking, backup and recovery, and identity and access management.

“Teams continue to neglect DevOps security, due in part to lack of attention to supply chain threats. Cloud-native applications have a long chain of dependencies, and those dependencies have dependences of their own,” the vendor explained.

“DevOps and security teams need to gain visibility into the bill of materials in every cloud workload in order to evaluate risk at every stage of the dependency chain and establish guardrails.”

Alongside its analysis of public data sources, Unit 42 was recently commissioned by a SaaS customer of Palo Alto Networks to run a red team exercise on its environment. It revealed critical flaws in its software development processes, which exposed the firm to attacks similar to those on SolarWinds and Kaseya.

“The customer whose development environment was tested in the red team exercise has what most would consider a mature cloud security posture,” the vendor claimed. “However, their development environment contained several critical misconfigurations and vulnerabilities, enabling the Unit 42 team to take over the customer’s cloud infrastructure in a matter of days.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

SolarWinds Attackers Develop New FoggyWeb Backdoor

SolarWinds Attackers Develop New FoggyWeb Backdoor

Microsoft has discovered a new post-exploitation backdoor attributed to the SolarWinds attackers, designed to help them gain admin-level access to active directory federation services (AD FS) servers.

Dubbed “FoggyWeb,” the malware has been in use since around April 2021, allowing the Russian-linked APT group known as Nobelium (aka APT29) to steal info from compromised servers and receive and execute additional malicious code.

AD FS are on-premises servers that support single sign-on (SSO) for cloud applications used in Microsoft environments. They, therefore, represent an attractive target for data thieves on the hunt for sensitive information.

“Once Nobelium obtains credentials and successfully compromises a server, the actor relies on that access to maintain persistence and deepen its infiltration using sophisticated malware and tools,” explained Ramin Nafisi, senior software security engineer at Microsoft.

“Nobelium uses FoggyWeb to remotely exfiltrate the configuration database of compromised AD FS servers, decrypted token-signing certificate, and token-decryption certificate, as well as to download and execute additional components.”

Microsoft has informed all customers currently being targeted by the malware, but it urged others who suspect they may be a victim to audit their entire on-premises and cloud infrastructure, to look for changes the threat actors may have made to maintain persistence.

It also recommended organizations remove user and app access and issue new, strong credentials. They should also use a hardware security module (HSM) to prevent the exfiltration of sensitive info by FoggyWeb, said Nafisi.

He listed multiple suggested techniques to harden and secure AD FS deployments, including restricting admin rights, deploying multi-factor authentication (MFA), removing unnecessary protocols and Windows features, sending AD FS logs to a SIEM, and using complex passwords with over 25 characters.

Since its discovery, the threat actors behind the infamous SolarWinds campaign, which compromised multiple US government departments, have been building out their toolset.

Following the Sunburst backdoor and Teardrop malware used in the attacks, they developed GoldMax, GoldFinder and Sibot malware for layered persistence and EnvyScout, BoomBox, NativeZone and VaporRage for early-stage infections.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains